📦 Pulsar

by Apache

🔍 What is Pulsar?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-22160

CRITICAL CVSS 9.8 May 26, 2021

This vulnerability in Apache Pulsar allows attackers to bypass JWT token authentication by using tokens with the 'none' algorithm, which are not properly validated. It affects any Apache Pulsar instan...

CVE-2022-34321

HIGH CVSS 8.2 Mar 12, 2024

Apache Pulsar Proxy has an improper authentication vulnerability that allows unauthenticated access to the /proxy-stats endpoint. This exposes connection statistics and allows logging level manipulati...

CVE-2024-27317

HIGH CVSS 8.4 Mar 12, 2024

This CVE describes a directory traversal vulnerability in Apache Pulsar Functions Worker where authenticated users can upload malicious JAR/NAR files containing path traversal sequences (like '..') in...

CVE-2023-51437

HIGH CVSS 7.4 Feb 7, 2024

This vulnerability allows attackers to forge SASL Role Tokens that pass signature verification due to timing discrepancies in Apache Pulsar's authentication provider. Attackers could potentially gain ...